A Question about FireWall logging

A Question about FireWall logging

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
A Question about FireWall logging carkaci 03-29-2006
Posted by on March 29, 2006, 3:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
In our company, we enable only the ACCEPTED packet logging (cisco
firewall) ? I wonder the advantage of deny or rejected pakets logging
also i.e. (full logging). Any idea ? What type of analysis can be done
at that time?


Posted by Duane Arnold on March 29, 2006, 3:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> In our company, we enable only the ACCEPTED packet logging (cisco
> firewall) ? I wonder the advantage of deny or rejected pakets logging
> also i.e. (full logging). Any idea ? What type of analysis can be done
> at that time?
>

I would think the ability to get a total picture of all traffic hitting the
FW that's being rejected. I particularly like to keep track or keep an eye
on remote IP(s) the same IP coming at the FW numerous times and run analysis
reporting on how many times the same IP is coming at the FW by day, week and
month. I have not done it that often maybe 3 or 4 times that I have set a
rule on my Watchguard that I denied specific IP(s) that were coming just a
little to hard, even if the unsolicited traffic was being rejected by the
FW. It's just me, but I don't like flying half blind and want to see all
aspects of what's happening from time to time.

Duane :)



Similar ThreadsPosted
Trustix firewall logging May 23, 2006, 10:13 am
What free/low-cost firewall solution best for logging all traffic? April 13, 2005, 8:55 pm
outpost firewall blocking http requests for no reason and without logging? February 6, 2007, 12:57 am
PIX not logging IDS to syslog December 21, 2005, 12:52 am
pix6.3 logging May 22, 2006, 6:54 am
Logging TCP events October 9, 2006, 9:54 am
SmartTracker Logging Issue February 5, 2008, 10:45 am
Setting up logging on my Linksys WRT54G July 17, 2004, 6:20 pm
Intrusion logging on cable internet March 22, 2006, 2:49 pm
Check Point NG Cluster Logging issue December 14, 2005, 8:08 pm

The site map in XML format XML site map

Contact Us | Privacy Policy